Quality Control · 13 August 2026 · 11 min read

Outbound calling compliance when an AI voice agent dials

Automate outbound and compliance stops being a question of what an agent said and becomes a question of what your script says. What the published statutes set as maximums, and how to hear every call instead of a sample.

OUTBOUND RISK, PER SCRIPT1One script line2Every call in thecampaign3Every call scored4One fix, whole campaignOne defect reaches every call in the campaign — and so does one correction.

What changes when the dialer is not a person

We ran call centres for about ten years, up to 1,500 live operators at peak, across France, Mexico and beyond, outbound campaigns among them. On a floor that size, compliance is a behaviour problem. Every operator has a script in front of them and a mouth of their own, and the two do not always agree. Someone skips the identification line because the shift is nearly over. Someone talks over a customer who is trying to say stop. Someone dials a number that should have been suppressed, because the suppression lived in a spreadsheet that was days behind the dialer.

Supervisors handle that the only way anyone can: by sampling. Pull a few calls per operator per month, listen, coach, move on. The risk is spread thin across everyone on the floor, and so is the detection. A bad habit belongs to one person and shows up in one person's calls, which is why manual outbound feels survivable even when it is not.

Automate the same campaign and the improvisation stops. The agent says what the script says, on the first call and on the last one. That is a different kind of exposure, and it cuts in both directions. One badly worded line is now wrong on every call in the campaign rather than on some of them. One corrected line is right on every call from the moment you save it, with no coaching cycle in between and nobody quietly reverting to the old wording.

The actual shift

Automation moves outbound compliance from a per-agent behaviour problem to a per-script systems problem, which is worse if you are careless with it and considerably better if you are not.

One note before the specifics. Everything below is what the published statutes and rules say, quoted as maximums where they are maximums. It is not legal advice and we are not your counsel. What applies to your campaign depends on where you call, who you call and what basis you had for the number.

What the statutes put on the table

Two numbers get quoted in every outbound compliance conversation, and both of them are ceilings. The US TCPA statute sets a maximum of $1,500 per single call or text. The FTC Telemarketing Sales Rule sets a maximum penalty of $50,120 per Do-Not-Call violation. Maximum is the operative word in both sentences. These are the top of the range a court or a regulator can reach, not the price of an ordinary mistake, and repeating them as typical outcomes is the fastest way to lose the attention of operators who know better.

$1,500
statutory maximum per single call or text, US TCPA
$50,120
maximum penalty per Do-Not-Call violation, FTC Telemarketing Sales Rule

What makes those ceilings matter is not their height. It is that outbound exposure multiplies. A defect in one operator's habits touches the calls that operator makes. A defect in a script touches every record the campaign dials. The unit of risk stops being a call and becomes a list, and lists are long on purpose.

The litigation pattern follows from that arithmetic. An industry compilation of TCPA filing data counted 2,788 suits filed in 2024, up 67% in a single year, with 78% of them filed as class actions. Read those as a compilation rather than as a court statistic, because that is what they are. The shape is still legible: the claims worth filing are the ones that scale across a list, and a script defect scales across a list by construction.

Where the risk actually sits once a script is dialling

In an automated campaign, nearly everything a regulator would ask about is a line of configuration rather than a state of mind. That makes the list of things to get right short, specific and readable in advance.

None of those are personality traits. All of them can be inspected before a single number is dialled, which is something manual outbound never offered. You cannot inspect what an operator will feel like doing at the end of a Thursday shift. You can read a script line on Monday morning, and you can read the routing rule underneath it.

The reason a bad script runs for weeks

The failure most outbound teams actually have is not a legal failure. It is a detection failure, and it predates automation by decades.

The detection gap

In our own operations the share of recorded calls that ever got reviewed under manual QA stayed under 5%, and review meant a handful of calls per agent per month.

Any supervisor who has ever kept a scorecard will recognise that share. The recordings exist. Storage is not review. Almost none of them have been heard by anyone, which means a wrong line on a script is discovered by luck, by a complaint, or by a letter from someone's lawyer.

There is a reasonable objection here: a defect that fires on every call should surface in even a tiny sample. Sometimes it does. The defects that survive review are branch defects. The agent handles a stop request correctly when the person says remove me and badly when they say I never asked for this. The recording notice plays on the main path and is missing on the callback path. The transfer promises something the campaign cannot deliver, but only when a customer asks the one question that sends the conversation down that leg. Branches are a small share of calls, and a small share of an already small sample rounds to nothing.

The second problem with sampling is what the reviewer is listening for. QA scorecards are built around commercial quality: did the agent probe, did they handle the objection, did they ask for the appointment. The disclosure at the top of the call reads as boilerplate to a human ear, so a human ear skates straight over it. That opening is precisely where a plaintiff's lawyer starts.

Score every call, then fix in one place

A mechanical problem takes a mechanical answer. If the calls are placed by software, they can all be scored by software. In our own operations we score 100% of calls against the checks a campaign defines, rather than the handful per agent per month that manual QA gets through. That is our operating practice, not a research finding, and the distinction is worth stating in an article about compliance.

01
Write the checks down

Turn each obligation into a yes-or-no check against the transcript: was the company named, was the stop request honoured on first mention, was the notice delivered, did the transfer stay inside what the campaign can promise.

02
Score every call, not a sample

Every call gets every check on the day it happens, including the branches a supervisor would never have thought to pull.

03
Fix the line, not the person

A failed check points at a script line or a routing rule. You change it once and the next call is correct. There is no coaching cycle and no floor to retrain.

04
Re-score the history

When you add a check, run it back across calls you already have. A defect discovered today has a start date, and you want to know that date before somebody else establishes it for you.

Recorded calls ever reviewed under manual QA5%
under 5%, in our own operations
Calls scored in our own operations100%
our operating practice, not research

Two limits, said plainly. Scoring finds only what you wrote a check for, so a rule nobody encoded is a rule nobody enforces, and deciding what the checks should be stays human work. And no volume of scoring repairs a list you had no basis to call in the first place. Consent sits upstream of the script, in your CRM and in whatever the record says about where the number came from. An agent that reads a flawless disclosure to a person who should never have been dialled is a well-documented problem, not a solved one.

What we do not claim

A compliance page is where vendors reach for badges. We do not have them to show. Benerra has published no certification, no encryption standard, no service-level guarantee and no third-party audit, and we are not going to imply one here because the subject invites it. When a vendor's compliance story is a row of logos, ask which document sits behind each logo and who signed it.

What we can describe is operational and checkable. The script is a versioned object, so what the agent said on a given day is a matter of record rather than recollection. Every call in our own operations is scored against the checks the campaign defines. A defect is corrected in one place and stops recurring on the next call. Benerra is registered in Dubai (UAE), and for personal data originating in the European Union we rely on an EU representative under Article 27 of the GDPR.

That is a narrower promise than a wall of badges, and it is the one worth having. Automated outbound does not reduce your legal exposure on its own. It concentrates the exposure into text you can read, and it makes every call available for inspection instead of a few. Both of those only pay off if somebody looks.

Frequently asked questions

What is the maximum TCPA penalty for a single call?
The US TCPA statute sets a maximum of $1,500 per single call or text. That is a ceiling, not a typical outcome, and it is not what an ordinary matter resolves at. This is what the published statute says; it is not legal advice, and your counsel owns the question of what applies to your campaign.
What is the penalty for calling a number on the Do-Not-Call list?
The FTC Telemarketing Sales Rule sets a maximum penalty of $50,120 per Do-Not-Call violation. Again, a maximum rather than an expected cost. The reason it gets attention in automated outbound is multiplication: a suppression file the dialer never actually reads produces the identical error on every matching record in the list.
How much of a call recording archive does manual QA really review?
In our own operations the share of recorded calls that ever got reviewed under manual QA stayed under 5%, and review meant a handful of calls per agent per month. It is also why a badly worded script line can run for weeks before anyone hears it: the recordings are stored, but storage is not review.
Can every outbound call be checked for compliance if an AI voice agent makes it?
Yes, and that is the operational argument for automating outbound at all. In our own operations we score 100% of calls against the checks a campaign defines, instead of a handful per agent per month. That is our operating practice rather than a published study, and it covers only the checks somebody wrote down.
Does an AI voice agent have to tell people it is not human?
Disclosure requirements differ by jurisdiction and are moving. We disclose by default and would recommend it regardless of what a given jurisdiction currently requires: a caller who works it out halfway through and feels misled is a worse outcome than one who was told in the opening sentence. The legal question belongs to your counsel.
Do you need consent to record an outbound call?
It depends where the person you called is. Some jurisdictions require every party to consent to a recording, others do not. In an automated campaign the practical questions are whether your notice was written for the jurisdictions actually present in your list, and whether it plays on every path through the call, including callbacks and transfers.